A newly exploited zero-day vulnerability dubbed StyleSmuggler affects all versions of Magento and Adobe Commerce and is being used to install a Linux backdoor on vulnerable e-commerce websites.
Sansec recorded the first exploitation activity on September 4, including attacks against websites running the latest available security updates.
The e-commerce security company said Adobe Enterprise Support confirmed that Adobe is working on a security fix. However, Adobe has not provided a release schedule.
Magento is one of the world’s most widely used open-source e-commerce platforms. Adobe Magento and Adobe Commerce are installed on more than 160,000 websites, including approximately 14,000 sites ranked among the top one million websites worldwide.
StyleSmuggler Magento zero-day installs Linux backdoor
The StyleSmuggler exploit observed in the wild abuses Magento’s templating system through PHP code injection. Attackers use the vulnerability to generate a fake “failed payment” email and trigger arbitrary code execution on the server.
A successful attack installs a small Rust-based Linux backdoor that runs as a background process while attempting to impersonate legitimate system processes, including kworker/u:8:0. Newer versions disguise the malware as fc-cache and copy it to ~/.cache/fontconfig/fc-cache.
Sansec researchers said the attackers also create a cron job that runs every 30 minutes, providing persistence even after the malicious process is stopped.
Although Sansec has not observed additional activity after the backdoor was installed, the malware can communicate with remote infrastructure and receive commands from its operators.
Earlier versions of the backdoor used TLS and WebSockets to communicate with command-and-control (C2) servers. The latest version instead disguises its traffic as Network Time Protocol (NTP) communications.
The malware sends UDP packets to port 123 and uses hostnames resembling legitimate time-synchronization infrastructure. This technique is designed to conceal malicious traffic and help it pass through network firewalls.
The backdoor also uses services including ipify, icanhazip, ident.me, and ipinfo.io to identify the server’s public IP address. It checks the Linux TracerPid value for signs of analysis or tracing. If tracing is detected, the malware remains installed but does not display its beacon.
Sansec says an unexpected increase in Magento “Failed Payment Transaction Reminder” emails could indicate exploitation. Website administrators should also monitor for unusual kworker or fc-cache processes, suspicious cron jobs, and unfamiliar files in temporary or cache directories.
Organizations that suspect a Magento or Adobe Commerce compromise should immediately investigate their systems, remove unauthorized persistence mechanisms, and rotate Magento administrator, database, API, SSH, and other potentially exposed credentials.
As of this writing, Adobe has not released a patch for the StyleSmuggler zero-day. The company’s next scheduled security release is expected on September 8.
Until an official fix is available, Sansec recommends that website administrators disable GraphQL as a temporary mitigation where operationally possible.
BleepingComputer contacted Adobe to ask whether a StyleSmuggler security update will be included in the upcoming release, but the company has not yet responded.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



